Threat reportVulnerabilityTL-2026-0040

Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan

highMONITORING

Microsoft NTLM Deprecation (TL-2026-0040), also tracked as NTLM Relay, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-02-03. It has no confirmed attribution, affects Microsoft Windows Server and Windows Client, maps to 19 MITRE ATT&CK techniques (T1003, T1003.003, T1018), and is covered by 15 detection rules and 40 indicators of compromise.

CVSS
7.5/10High
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
15SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0040

Threat ID
TL-2026-0040
Also known as
NTLM Relay, Pass-the-Hash, NTLM Deprecation
Severity
HIGH
CVSS
7.5 (N/A - Protocol Weakness)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
VARIOUS
Target sectors
Enterprise, Government, Financial Services, Healthcare, Education, Manufacturing, All sectors running Active Directory
Target regions
Global
Detection rules
15
Indicators of compromise
40

Malware and tooling in Microsoft NTLM Deprecation

Malware and tooling: Impacket ntlmrelayx.py / Responder / PetitPotam.py / DFSCoerce.py / mimikatz, ntlmrelayx.py / Responder / PetitPotam.py / DFSCoerce.py / mimikatz / Rubeus

How Microsoft NTLM Deprecation works

Microsoft's three-stage NTLM deprecation plan: enterprise migration timeline from NTLM to Kerberos/Negotiate, legacy application compatibility matrix, and the operational risk of a 30-year protocol phase-out across millions of Active Directory environments.

Microsoft announced the formal deprecation of NTLM authentication in June 2024 with a phased three-stage approach to remove the protocol from Windows. This threat covers the ENTERPRISE MIGRATION perspective — distinct from TL-0018 (NTLM enforcement and the attack surface). Stage 1 (Audit & Discovery, 2024-2025): Organizations enable NTLM auditing via Group Policy (Network Security: Restrict NTLM: Audit NTLM authentication in this domain / Audit Incoming NTLM Traffic) to discover all applications, services, and systems still using NTLM. Windows Event IDs 8001-8004 log NTLM usage. This phase reveals the true scope of NTLM dependency — most enterprises discover 10-40% of authentication traffic is still NTLM. Stage 2 (Selective Restriction, 2025-2026): Organizations begin blocking NTLM for specific applications and services using NTLM restriction policies (Network Security: Restrict NTLM: NTLM authentication in this domain / Add server exceptions). Server-side and client-side exceptions manage compatibility. IAM Credential Roaming exceptions handle legacy device authentication. This phase exposes the COMPATIBILITY MATRIX problem: legacy applications (pre-2010 LOB apps, older ERP systems, embedded devices, legacy printers, cross-forest trusts, non-Windows clients) that cannot negotiate Kerberos. Stage 3 (Full Deprecation, 2026+): Microsoft removes NTLM components from Windows. NTLMv1 removed first (immediate security gain — NTLMv1 hashes are crackable in seconds). NTLMv2 removal follows (harder — NTLMv2 is still cryptographically weak but some services have no Kerberos path). The compatibility matrix is the critical challenge: (1) Legacy LOB applications: custom-built .NET/COM applications using NTLM directly via SSPI rather than Negotiate. Many have hardcoded NTLM providers. Remediation: code modification or wrapper. (2) Cross-forest trusts: NTLM is required for some cross-forest authentication scenarios where Kerberos trust paths don't exist. Remediation: establish Kerberos forest trusts or migrate to Azure AD/Entra ID. (3) Non-Windows clients: Linux/macOS clients using NTLM for SMB/CIFS access. Remediation: configure Kerberos on non-Windows clients (krb5.conf + keytab). (4) Embedded devices: printers, scanners, ICS/OT devices with hardcoded NTLM. Remediation: network segmentation + service accounts with NTLM exceptions. (5) Older SQL Server instances: pre-2016 SQL Server using NTLM for Windows authentication. Remediation: upgrade or configure SPN for Kerberos. (6) Web applications using Windows Integrated Authentication (WIA) with NTLM fallback: IIS sites configured for NTLM rather than Negotiate. Remediation: change IIS authentication provider order. The migration risk is operational disruption: blocking NTLM without completing the compatibility audit causes authentication failures that break production applications, prevent users from accessing file shares, and disrupt cross-domain trust relationships. The security risk of NOT migrating: NTLM relay attacks (ntlmrelayx), pass-the-hash, reflection attacks, and credential theft via LLMNR/NBT-NS poisoning remain the #1 Active Directory attack surface. Every day NTLM remains enabled is another day attackers can relay, capture, and crack NTLM hashes.

MITRE ATT&CK techniques used in TL-2026-0040

credential-access

T1003 OS Credential Dumping; T1003.003 NTDS; T1040 Network Sniffing; T1110 Brute Force; T1187 Forced Authentication; T1557 Adversary-in-the-Middle; T1557.001 Name Resolution Poisoning and SMB Relay; T1649 Steal or Forge Authentication Certificates

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

lateral-movement

T1021 Remote Services

execution

T1047 Windows Management Instrumentation

defense-evasion

T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1550.002 Pass the Hash

persistence

T1098 Account Manipulation

initial-access

T1190 Exploit Public-Facing Application

privilege-escalation

T1548 Abuse Elevation Control Mechanism

resource-development

T1588 Obtain Capabilities

Affected products and versions in Microsoft NTLM Deprecation

  • Microsoft — Windows Server and Windows Client
    Vulnerable versions: All versions using NTLM
    Fixed in: Kerberos-only configurations

Remediation for Microsoft NTLM Deprecation

Immediate actions

  • Audit NTLM usage with provided detection queries
  • Identify applications and services requiring NTLM
  • Disable NTLMv1 via Group Policy immediately
  • Enable NTLM auditing (GPO: Network security: Restrict NTLM)
  • Block NTLM where possible using network policies

Workarounds

  • Restrict NTLM to specific servers/applications via GPO
  • Enable Extended Protection for Authentication (EPA)
  • Require NTLMv2 minimum via LmCompatibilityLevel

Longer-term hardening

  • Migrate all authentication to Kerberos
  • Upgrade or replace legacy applications requiring NTLM
  • Implement modern authentication (Azure AD, OIDC)
  • Prepare for NTLM-disabled Windows versions
  • Deploy credential guard to protect NTLM hashes

Weaknesses (CWE) in Microsoft NTLM Deprecation

CWE-294, CWE-327

Timeline of Microsoft NTLM Deprecation

  • NTLM authentication introduced in Windows NT 3.1. Challenge-response protocol replacing plaintext LAN Manager authentication. Designed for single-domain environments. Source: Microsoft.
  • Discovered
  • First Exploitation
  • Windows 2000 introduces Kerberos v5 as the preferred authentication protocol for Active Directory. NTLM remains as fallback for backward compatibility. Microsoft recommends Kerberos over NTLM. Source: Microsoft.
  • Windows 7 / Server 2008 R2 introduces NTLM restriction and auditing Group Policy settings. Organizations can now audit and selectively block NTLM usage. Source: Microsoft.
  • Impacket ntlmrelayx and Responder become mature attack tools. NTLM relay attacks industrialized — automated capture and relay of NTLM hashes in penetration testing and real attacks. Source: Multiple.
  • PetitPotam attack (CVE-2021-36942) demonstrates NTLM relay via MS-EFSRPC. Forces domain controller to authenticate to attacker via NTLM — enables full domain compromise. Source: Topotam/GitHub.
  • DFSCoerce attack discovered — NTLM relay via MS-DFSNM. Another coercion vector forcing NTLM authentication from domain controllers. Compounds the urgency for NTLM deprecation. Source: GitHub.
  • CVE-2023-23397: Microsoft Outlook NTLM hash leak via calendar invitation. Zero-click NTLM hash theft exploited by Russian APT28. Demonstrates that NTLM vulnerabilities are actively weaponized. Source: Microsoft MSRC.
  • Microsoft formally announces NTLM deprecation. Three-stage phase-out plan published. Windows Server 2025 includes built-in deprecation features. 30+ year protocol begins sunset. Source: Microsoft.
  • Disclosed
  • Windows Server 2025 released with enhanced NTLM auditing, restriction controls, and deprecation path tooling. Stage 1 tooling available for enterprises. Source: Microsoft.
  • Stage 1 (Audit & Discovery) active. Enterprises discover 10-40% of authentication traffic is NTLM. Legacy LOB applications, cross-forest trusts, and embedded devices identified as primary blockers. Source: Industry reports.
  • Stage 2 (Selective Restriction) begins for early adopters. NTLMv1 disabled across most environments. NTLMv2 restrictions applied to migrated services. Exception lists grow for legacy systems. Source: Microsoft guidance.
  • Stage 3 (Full Deprecation) planning underway. NTLMv1 removal from Windows confirmed. NTLMv2 removal timeline tied to enterprise migration progress. Legacy device exception strategy required. Source: Microsoft roadmap.
  • Patch Available
  • As of 2026-05-29, this NTLM-deprecation lifecycle threat remains active: Microsoft's three-stage phase-out is mid-flight (Phase 1 auditing live on Server 2025/Win11 24H2, NTLMv1 already removed, Phase 2 IAKerb/local-KDC due H2 2026, Oct 2026 BlockNTLMv1SSO enforce, Phase 3 undated). The relay/pass-the-hash/PetitPotam attack surface is still exploited in 2026, so MONITORING holds.

Sources cited for Microsoft NTLM Deprecation

Detection coverage for TL-2026-0040

As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0040 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

15 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats